Copy code
Код:
gmer.exe -del service geyekrybyxcnoe
gmer.exe -del reg "HKLM\SYSTEM\ControlSet003\Services\geyekrybyxcnoe"
gmer.exe -del reg "HKLM\SYSTEM\CurrentControlSet\Services\geyekrybyxcnoe"
gmer.exe -del file "c:\windows\system32\drivers\geyekrlfyeoayv.sys"
gmer.exe -del file "c:\windows\system32\geyekrpacxljgx.dll"
gmer.exe -del file "c:\windows\system32\geyekrucdddrot.dat"
gmer.exe -del file "c:\windows\system32\geyekrvjjdanyu.dll"
gmer.exe -del file "c:\windows\system32\geyekrvcvvkyxj.dat"
gmer.exe -del file "c:\windows\system32\geyekrwsp.dll"
in a new text file, save it as 123.bat in the same directory, where gmer.exe saved and let it run with a double click.
After reboot:
Execute following script in Manual Healing
Код:
begin
SetAVZGuardStatus(True);
DeleteFileMask('%systemroot%\','geyekr.*',false);
DeleteFileMask('%systemroot%\system32','geyekr.*',false);
DeleteFileMask('%systemroot%\system32\drivers','geyekr.*',false);
ExecuteSysClean;
RebootWindows(true);
end.
After reboot:
repeat the GMER - log